Windbg AnalyzerSAFE
Model Context Protocol for WinDbg.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/svnscha/mcp-windbg/actions/workflows/ci.yml) [](https://svnscha.github.io/mcp-windbg/) [](https://pypi.org/project/mcp-windbg/) [](LICENSE)
A Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis, user-mode remote debugging, and kernel debugging.
Overview
This server drives the Windows debuggers - CDB for user mode (dumps and -remote) and KD for kernel targets (-k) - so you can debug in natural language: "Show me the call stack and explain this access violation" or "Open a kernel session and tell me which driver bugchecked."
It is not a magical auto-fix. It is a Python wrapper around cdb.exe / kd.exe that lets an LLM run real debugger commands and reason about the output.
Features
- Crash dump analysis - open a
.dmp/.mdmp/.hdmpand get automated triage (!analyze -v, stacks, modules, threads) in a single call. - User-mode remote debugging - attach to a live
cdb/WinDbg debug server (-remote) over TCP, a named pipe, or COM, and break in on demand. - Kernel debugging - attach to a kernel target (
-k, driven bykd.exe) over KDNET, a named pipe, or serial; the server waits for the target and breaks in for you. - Run any WinDbg/KD command - drive an open session with arbitrary commands (
kb,!process 0 0,!heap,lm, ...) de
e7f795e5326cOBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-windbg -- uvx mcp-windbg==1.3.0
claude mcp add mcp-windbg -- uvx mcp-windbg==1.3.0
Exposed tools (10)
7 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
close_cdb_session | read | |
close_kd_session | read | |
list_dumps | read | |
open_cdb_dump | read | |
open_cdb_remote | read | |
open_kd_session | read | |
run_cdb_command | write | |
run_kd_command | write | |
send_ctrl_break | write | |
wait_for_break | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (7)
.release-please-manifest.json
python -m mkdocs serve # live preview at http://127.0.0.1:8000
The endpoint is then `http://127.0.0.1:8000/mcp`. See
It serves MCP at `http://127.0.0.1:8000/mcp`. Pass the same server options as usual, for example
# python -m mkdocs serve # live preview at http://127.0.0.1:8000
url = f"http://127.0.0.1:{port}/mcp"src/mcp_windbg/tests/dumps/DemoCrash1.exe.7088.dmp
Gates applied: no_behavioural_pass.
e7f795e5326cfull audit observations/trust-audit/mcp-server/svnscha__windbg-analyzer.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | e7f795e5326c | SAFE | B | 89 | first audit |
Questions
What is the Windbg Analyzer MCP server?
Model Context Protocol for WinDbg.
What tools does Windbg Analyzer expose?
10 in total: 7 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Windbg Analyzer safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Windbg Analyzer need?
No credential environment variables were found in its source, so it appears to need none.
How does Windbg Analyzer run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-windbg.
How current is this page?
The grade is for one exact copy of the source (e7f795e5326c), read on 2026-09-24. The repository is watched and re-audited when it changes.